FortiGate policy match-order explainer
Paste an ordered FortiGate policy list and, optionally, a packet, and see which policy wins and why. It walks the list top-down showing the first field that ruled each policy out, names the policies that can never be reached because something broader sits above them, and applies the virtual-IP matching rules that ordering alone does not solve. Local and offline.
Security & WAFOne per line: id | incoming interface | outgoing interface | source | destination | service | action | flags. Flags are optional and may include vip, match-vip and disabled.
incoming interface | outgoing interface | source | destination | service
API endpointGEThttps://ronutz.com/api/v1/fortigate-policy-match-orderDocumented, not served. Opens the specification.